Appl. No. 09/922,209 
Amdt. dated Sept. 1, 2008 

Reply to Notice of Non-Compliant Amdt. of Jun. 30, 2008 

Amendments to the Claims: 

This listing of claims will replace all prior versions, and listing, of claims in the 
application: 

Listing of Claims: 

Claim 1 (withdrawn): A method comprising the steps of: 

(a) generating hash data based on at least one of a universal resource locator 
(URL) of a resource, resource access right data defining restriction(s) on a web access 
device (WAD) and/or user thereof to access the resource, and an internet protocol (IP) 
address of the WAD; 

(b) generating a secure URL by combining the hash data, URL, and resource 
access right data; and 

(c) generating a web page document including the secure URL that can be used to 
generate a request for the resource. 

Claim 2 (withdrawn): The method as claimed in claim 1 further comprising the step of: 

(d) transmitting the web page document including the secure URL to the WAD in 
response to a request for the web page document from the WAD. 

Claim 3 (withdrawn): The method as claimed in claim 1 wherein the hash data is further 
generated based on key data. 

Claim 4 (withdrawn): The method as claimed in claim 3 wherein steps (a)-(d) are 
performed at a resource provider subsystem (RPS), the method further comprising the 
step of: 

(d) transmitting the key data from the RPS to a resource distribution subsystem 
(RDS) hosting the resource so that, if the secure URL is activated by the WAD to 
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generate a request for the resource to the RDS, the RDS can verify that the resource 
access right data has not been modified other than by the RPS. 

Claim 5 (withdrawn): The method as claimed in claim 1 wherein the resource access 
right data includes at least one of: 

1) an authorized Internet protocol (IP) address or IP address range; 

2) lifespan data indicating the lifespan indicating a time period over which 
requests for accessing a resource are valid; and/or 

3) maximum reference data indicating a maximum number of times a web access 
device and/or user thereof can access a resource. 

Claim 6 (withdrawn): A method comprising the steps of: 
at a resource provider subsystem (RPS), 

(a) receiving a request for a web page from a web access device via a network, the 
request including a network address of the web access device; 

(b) determining resource access right data for the web access device and/or a user 
thereof, the resource access right data defining restriction(s) for the web access device 
and/or user thereof to access a resource; 

(c) securing a universal resource locator (URL) for the resource by generating 
hash data based on at least one of the URL, a network address of the web access device, 
and/or resource access right data, and combining the URL, resource access right data, and 
hash data together in the web page such that the secure URL can be used to generate a 
request for the resource; and 

(d) transmitting the web page having the secure URL to the web access device via 
the network in response to the request received in step (a) from the web access device. 

Claim 7 (withdrawn): The method as claimed in claim 6 wherein the hash data is 
generated further using key data corresponding to the web access device and/or user 
thereof, the method further comprising the step of: 
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(e) transmitting key data corresponding to the web access device and/or user 
thereof to a resource distribution subsystem (RDS) hosting the resource so that, if the 
secure URL is activated by the web access device to generate a request for the resource to 
the RDS, the RDS can verify that the resource access right data has not been modified 
other than by the RPS. 

Claim 8 (withdrawn): The method as claimed in claim 6 wherein the network address of 
the web access device is an internet protocol (IP) address. 

Claim 9 (currently amended): A method comprising the steps of: 

(a) receiving a signal at a web server requesting a web page document from a web 
access device (WAD), the signal including an Internet protocol (IP) address of the WAD; 

(b) retrieving data for the requested web page document including a universal 
resource locator (URL) of one or more resources referenced in the requested web page 
document; 

(c) retrieving resource access right data for the each resource URL referenced in 
the requested web page document using the IP address of the (WAD) and/or user name 
and password established through a log-in procedure; 

(d) generating hash and/or encrypted data to generate secure resource access right 
data for each resource URL referenced in the requested web page document ; 

(e) combining the secure resource access right data for each resource URL with 
the respective resource URL to generate a secure resource URL for each resource URL 
referenced in the requested web page document ; 

(f) generating the requested web page document including the secure resource 
URL(s) that can be used by the WAD to generate a request for the one or more each 
resource[[s]]; 

(g) transmitting the web page document including the secure resource URL(s) to 
the WAD; and 
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wherein steps (b)-(g) are performed at the web server in response to the received 
signal from the WAD. 

Claim 10 (withdrawn): A method comprising the step of: 
at a web access device (WAD), 

(a) transmitting a signal requesting a web page document to a resource provider 
subsystem (RPS); and 

(b) receiving the web page document having a secure universal resource locator 
(URL) with hash data, URL, and resource access right data, wherein the secure URL can 
be used to generate a signal requesting a resource, in response to the request. 

Claim 11 (withdrawn): The method as claimed in claim 10 further comprising the step 
of: 

(c) activating the secure URL with the WAD to transmit a signal requesting 
access to athe resource designated by the URL to a resource distribution subsystem 
(RDS); and 

(d) accessing the resource with the WAD if the RDS determines that access to the 
resource is authorized based on the hash data and resource access right data contained in 
the request signal. 

Claim 12 (withdrawn): A method comprising the steps of: 

(a) at a web access device (WAD), generating and transmitting a request for a 
web page document to a resource provider subsystem (RPS); 

(b) receiving the requested web page document having a secure universal resource 
locator (URL) with secured resource access right data from the resource provider 
subsystem (RPS); 

(c) executing a browser application and the web page document having the secure 
URL with the WAD to generate and transmit a signal to request a resource distribution 
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subsystem (RDS) to provide access to a resource identified by the secure URL, the 
request signal including the URL and secure resource access right data; and 

(d) if access to the resource is permitted by the RDS, accessing the resource with 
the WAD. 

Claim 13 (withdrawn): The method as claimed in claim 12 wherein the step (d) 
comprises the substeps of: 

(dl) receiving at the WAD resource data from the RDS; 

(d2) storing the resource data in memory of the WAD; 

(d3) executing an application with the WAD based on the resource data to 
generate a signal; and 

(d4) generating a display with the WAD based on the signal generated in the 
substep (d3). 

Claim 14 (withdrawn): The method as claimed in claim 12 wherein the step (d) 
comprises the substeps of: 

(dl) receiving a program module resource from the RDS; 

(d2) loading the program module resource into memory of the WAD; 

(d3) executing the program module resource with the WAD to generate a signal; 

(d4) storing the signal(s) in memory; and 

(d5) generating a display with the WAD based on the signal generated in the 
substep (d4). 

Claim 15 (withdrawn): The method as claimed in claim 12 wherein the step (d) 
comprises the substeps of: 

(dl) receiving at the WAD via the network a signal from the RDS generated 
based on execution of a server application by the RDS; 

(d2) storing the received signal in the memory of the WAD; 
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(d3) generating with the WAD a display signal based on the signal received in the 
substep (dl); 

(d4) generating a display with the WAD based on the display signal; 
(d5) executing a client application with the WAD to generate a signal based on 
the signal from the RDS; and 

(d6) transmitting the signal(s) to the RDS via the network. 

Claim 16 (withdrawn): The method as claimed in claim 12 further comprising the step 
of: 

(d7) receiving input data at the WAD from a user, the client application executed 
in step (d5) based on the input data. 

Claim 17 (withdrawn): A method comprising the steps of: 
at a resource distribution subsystem (RDS), 

(a) receiving a signal requesting access to a resource from a web access device 
(WAD), the signal generated from a web page containing a secure universal resource 
locator (URL) combining at least a URL, resource access right data, and hash data; 

(b) verifying that the resource access right data as set by a resource provider 
subsystem (RPS) has not been changed, using the hash data; 

(c) if the verifying establishes that the resource access right data has not been 
changed, determining whether access to the resource is permitted to the WAD and/or user 
thereof based on the resource access right data; and 

(d) if the resource access right data indicates that the WAD and/or user thereof is 
authorized to access the resource, permitting access to the resource to the WAD and/or 
user thereof. 

Claim 18 (withdrawn): The method as claimed in claim 17 wherein the resource access 
right data includes at least one of: 

1) an authorized Internet protocol (IP) address or IP address range; 
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2) lifespan data indicating the lifespan indicating a time period over which 
requests for accessing a resource are valid; and 

3) maximum reference data indicating a maximum number of times a web access 
device and/or user thereof can access a resource. 

Claim 19 (withdrawn): The method as claimed in claim 17 wherein the hash data is 
generated based on the URL, resource access right data, and key data, the method further 
comprising the step of: 

(e) receiving key data from the RPS for use in verifying in step (b) that the 
resource access right data has not changed from establishment by the RPS. 

Claim 20 (withdrawn): The method as claimed in claim 17 wherein the key data includes 
a key and optionally at least one of: 

1) a second URL identifying the RPS; 

2) start date/time data identifying a date and time at which a key is valid; 

3) end date/time data identifying a date and time at which a key becomes invalid; 

4) lifespan data indicating a period of time over which the key is valid; 

5) key index data identifying the key from among a plurality of different keys; 

6) hash identifier data indicating to the RDS a hash algorithm to be performed to 
generate the hash data; 

7) encryption data indicating an encryption model and/or algorithm used to 
encrypt and decrypt resource access right data; and 

8) format fields data indicating the number of fields in the signal requesting 
access to the resource. 

Claim 21 (withdrawn): A method comprising the steps of: 

(a) receiving a signal requesting access to a resource, wherein the signal was 
generated from a web page containing a secure universal resource locator (URL) 
combining a URL with secured resource access right data; 
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(b) extracting an Internet protocol (IP) address from the secured resource access 
right data; 

(c) comparing the extracted IP address with the IP address included in a hypertext 
transport protocol (HTTP) message of the request signal; and 

(d) authenticating that the IP address of the secured resource access right data 
corresponds to the IP address of a device requesting access to the resource, based on the 
comparing of step (c). 

Claim 22 (withdrawn): The method as claimed in claim 21 further comprising the step 
of: 

(e) terminating the request signal if the authenticating of step (d) indicates that the 
IP address of the secured resource access right data does not match the IP address 
extracted from the HTTP message. 

Claim 23 (withdrawn): The method as claimed in claim 22 further comprising the steps 
of: 

(e) if the authenticating of step (d) indicates that the IP address of the secure 
resource access right data matches the IP address of the device requesting access to the 
resource, obtaining a key corresponding to the IP address; 

(f) verifying whether the key is valid based on data corresponding to the key in a 
secure content key database; 

(g) generating hash data based on at least the IP address, URL, and key; and 

(h) verifying that the hash data generated in the step (g) matches the hash data 
included in the request signal received in the step (a). 

Claim 24 (withdrawn): The method as claimed in claim 23 further comprising the steps 
of: 



Page 9 of 22 



Appl. No. 09/922,209 
Amdt. dated Sept. 1, 2008 

Reply to Notice of Non-Compliant Amdt. of Jun. 30, 2008 

(i) terminating the request signal if the verifying of the step (h) indicates that the 
hash data generated in the step (g) does not match the hash data included in the request 
signal received in the step (a). 

Claim 25 (withdrawn): The method as claimed in claim 23 further comprising the steps 
of: 

(i) determining whether access to a resource is to be provided to a device 
identified by the IP address, based on the resource access right data included in the 
request signal; 

(j) retrieving the resource based on the URL included within the request signal; 

and 

(k) providing access to the resource to a device identified by the IP address if the 
determining of step (j) indicates that access to the resource is to be provided, based on the 
URL. 

Claim 26 (withdrawn): The method as claimed in claim 25 further comprising the steps 
of: 

(1) retrieving resource access right data from a database, the determining of step 
(j) based further on whether the IP address of the request signal is authorized to access 
the resource indicated by the URL of the request signal, based on the retrieved resource 
access right data. 

Claim 27 (withdrawn): The method as claimed in claim 26 further comprising the steps 
of: 

(m) terminating the request signal if the determining of the step (1) indicates that 
access to the resource is not to be provided based on the resource access right data 
included in the request signal. 
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Claim 28 (withdrawn): The method as claimed in claim 26 wherein the resource access 
right data retrieved in the step (k) includes maximum reference data and reference count 
data, the method further comprising the step of: 

(n) incrementing the reference count data to indicate that access to the resource 
has been requested by the request signal; 

(o) comparing the incremented reference count data with the maximum reference 
count data; and 

(p) providing access to the resource if the comparing of step (o) indicates that the 
incremented reference count data does not exceed the maximum reference count data. 

Claim 29 (withdrawn): The method as claimed in claim 26 wherein the resource access 
right data retrieved in the step (k) includes lifespan data for access to the resource 
indicated by the URL, the method further comprising the steps of: 

(m) determining a time and date of receiving the request signal in step (a); 

(n) comparing the lifespan data with the time and date of receiving the requesting 
signal; and 

(o) determining that the IP address of the request signal is authorized to access the 
resource, if the comparing of the step (n) indicates that the time and date of receiving the 
request signal is within the lifespan data. 

Claim 30 (withdrawn): The method as claimed in claim 29 wherein the resource access 
right data retrieved in the step (k) includes URL/resource provider identification data, the 
method further comprising the step of: 

(p) retrieving the resource from a resource provider subsystem via the Internet, 
based on the URL/resource provider identification data, the retrieved resource used to 
provide access to the resource in the step (k). 
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Claim 31 (withdrawn): The method as claimed in claim 30 wherein the resource access 
right data retrieved in the step (1) includes retrieval key data used to decrypt the resource 
retrieved in the step (p). 

Claim 32 (currently amended): A method comprising the steps of: 

(a) receiving a signal at a web server requesting a web page document from a web 
access device (WAD), the signal including an Internet protocol (IP) address of the WAD; 

(b) retrieving data for the requested web page document including a universal 
resource locator (URL) of one or more resources referenced in the requested web page 
document; 

(c) retrieving resource access right data for each resource URL referenced in the 
requested web page document using the IP address of the (WAD) and/or user name and 
password established through a log-in procedure; 

(d) generating hash and/or encrypted data to generate secure resource access right 
data for each resource URL referenced in the requested web page document; 

(e) combining the secure resource access right data for each resource URL with 
the respective resource URL to generate a secure resource URL for each resource URL 
referenced in the requested web page document; 

(f) generating the requested web page document including the secure resource 
URL(s) that can be used by the WAD to generate a request for each resource; 

(g) transmitting the web page document including the secure resource URL(s) to 
the WAD; 

(a)£h) receiving a request signal at a web server generated by the WAD using the 
secure resource URL to requesting]] access to [[a]] the resource , the request signal 
including a universal resource locator (URL), secured resource access right data, and an 
Internet protocol (IP) address of a wob access device (WAD) requesting access to the 
resource, and hash data, wherein the request signal was generated from a web page 
document requested by the WAD that was generated by the web server and contains a 
secure URL combining the hash data, URL and secured resource access right data ; 
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(b)£i) verifying whether key data is valid based on data corresponding to the key 
data in a secure content key database; 

(e)(j) if the key data is verified as valid in step (b)£i), generating hash data based 
on at least the IP address, URL, and the key data; 

(d) £k) verifying that the hash data generated in the step (e)£j) matches the hash 
data included in the request signal received in the step (a)£h); and 

wherein steps (b)-fd ¥g) and (i)-(k) are performed at the web server in response to 
the received signals from the WAD. 

Claim 33 (currently amended): The method as claimed in claim 32 further comprising 
the steps of: 

(e) (1) terminating the request signal if the verifying of the step (4)(k) indicates that 
the hash data generated in the step (e){J) does not match the hash data included in the 
request signal received in the step (a)(h). 

Claim 34 (currently amended): The method as claimed in claim 33 further comprising 
the steps of: 

ffl (m) determining whether access to a resource is to be provided to a device 
identified by the IP address, based on the resource access right data included in the 
request signal; and 

(g) £n) providing access to the resource to a device identified by the IP address if 
the determining of the step (f)£m) indicates that access to the resource is to be provided. 

Claim 35 (currently amended): The method as claimed in claim 34 further comprising 
the steps of: 

(h) £o) retrieving resource access right data from a database, the determining of 
step (f)(m) based further on whether the IP address of the request signal is authorized to 
access the resource indicated by the URL of the request signal, based on the retrieved 
resource access right data. 
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Claim 36 (currently amended): The method as claimed in claim 32 wherein the request 
signal received in step (a)(h) includes key index data, the method further comprising the 
step of: 

(e) retrieving the key data from the secure content key database using the key 
index data. 

Claim 37 (currently amended): The method as claimed in claim 32 wherein the step 
(b)£i) comprises the substeps of: 

(W-)£il) determining a date and time of receiving the request signal in the step 

(a) £h); 

fb2 4(i2) retrieving start date/time data and end date/time date from a database; 

(b3)£i3) comparing the date and time of the request signal with the start date/time 
data and end date/time data; and 

(b4)£i4) determining whether the key data is valid, based on the comparing of the 
step &3¥i3). 

Claim 38 (currently amended): The method as claimed in claim 32 wherein the step 

(b) £i) comprises the substeps of: 

(M){il} determining a date and time of receiving the request signal in the step 

(a)£h); 

fb2 4(i2) retrieving lifespan data from a database; 

(b3)£i3) comparing the date and time of receiving the request signal with the 
lifespan data; and 

(b4)£i4) determining whether the key data is valid, based on the comparing of the 
step &3¥i3). 
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Claim 39 (withdrawn): A method comprising the steps of: 

(a) receiving via the Internet a request signal including a universal resource 
locator (URL) indicating a location of a resource, secured resource access right data 
indicating rights of a device to access the resource, and an Internet protocol (IP) address 
of the device, wherein the request signal was generated from a web page containing a 
secure URL combining the URL and secured resource access right data; 

(b) determining whether access to the resource is to be provided to the device 
identified by the IP address, based on secured resource access right data included in the 
request signal; and 

(c) providing access to the resource to a device identified by the IP address if the 
determining of the step (c) indicates that access to the resource is to be provided. 

Claim 40 (withdrawn): The method as claimed in claim 39 further comprising the step 
of: 

(d) terminating the request signal if the determining of the step (b) indicates that 
access to the device is not authorized. 

Claim 41 (withdrawn): The method as claimed in claim 39 wherein said step (c) 
comprises the substep of transmitting the resource to the device via the Internet. 

Claim 42 (withdrawn): The method as claimed in claim 39 further comprising the step 
of: 

(d) authenticating the request signal if an Internet protocol (IP) address of the 
URL in the request signal matches a URL of the device contained in the resource access 
right data of the request signal. 
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Claim 43 (withdrawn): The method as claimed in claim 39 further comprising the steps 
of: 

(d) retrieving resource access right data from a database, the determining of step 
(b) based further on whether the IP address of the request signal is authorized to access 
the resource indicated by the URL of the request signal, based on the retrieved resource 
access right data. 

Claim 44 (withdrawn): The method as claimed in claim 39 further comprising the step 
of: 

(d) verifying validity of key data; 

(e) generating hash data based on at least the URL and the key data; 

(f) comparing the hash data generated in step (e) with hash data included in the 
received request signal; 

(g) determining whether the hash data generated in step (e) matches the hash data 
generated in the request signal, based on the comparing of the step (f), the access to the 
resource provided in step (c) if the determining of step (g) establishes that the hash data 
match. 

Claim 45 (withdrawn): The method as claimed in claim 44 wherein the step (d) 
comprises the substeps of: 

(dl) determining a date and time of receiving the request signal in the step (a); 

(d2) retrieving start date/time data and end date/time date from a database; 

(d3) comparing the date and time of the request signal with the start date/time data 
and end date/time data; and 

(d4) determining whether key data is valid, based on the comparing of the step 
(b3), steps (e) through (g) performed if the key data is determined to be valid and not 
otherwise. 
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Claim 46 (withdrawn): The method as claimed in claim 44 wherein the step (d) 
comprises the substeps of: 

(dl) determining a date and time of receiving the request signal in the step (a); 

(d2) retrieving lifespan data from a database; 

(d3) comparing the date and time of receiving the request signal with the lifespan 
data; and 

(d4) determining whether key data is valid, based on the comparing of the step 
(b3), steps (e) through (g) performed if the key data is determined to be valid and not 
otherwise. 

Claim 47 (withdrawn): A system using the Internet, the system comprising: 

at least one web access device (WAD) executing a browser application, the WAD 
generating a signal requesting a web page document having a secure universal resource 
locator (URL), receiving the web page document having the secure URL, displaying the 
web page document having the secure URL, and generating a signal requesting a resource 
indicated by the secure URL of the web page document; 

a resource provider subsystem (RPS) coupled to receive via the Internet the signal 
requesting the web page document from the WAD, the RPS generating the secure URL to 
include resource access right data defining restriction(s) of the WAD and/or user thereof 
to access the resource indicated by the URL, the RPS transmitting the web page 
document with the secure URL to the WAD so that the WAD can generate a signal 
requesting the resource; and 

at least one resource distribution subsystem (RDS) coupled to receive via the 
Internet the signal from the WAD requesting access to the resource, the RDS determining 
whether the resource access right data has been changed from establishment by the RPS, 
and, if the RDS determines that the resource access right data has not been changed, the 
RDS determining whether the WAD and/or user thereof is authorized to access the 
resource using the resource access right data, the RDS permitting access to the resource if 
the WAD and/or user thereof is authorized to access the resource. 
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Claim 48 (withdrawn): The system as claimed in claim 47 wherein the resource access 
right data includes at least one of: 

1) an authorized Internet protocol (IP) address or IP address range; 

2) lifespan data indicating the lifespan indicating a time period over which 
requests for accessing a resource are valid; and/or 

3) maximum reference data indicating a maximum number of times a web access 
device and/or user thereof can access a resource. 

Claim 49 (withdrawn): The system as claimed in claim 47 wherein the hash data is 
generated by the RPS based on the URL, resource access right data, and key data, and the 
RDS stores the key data used by the RPS, the RDS verifying that the resource access 
right data has not changed from establishment by the RPS using the key data. 

Claim 50 (withdrawn): The system as claimed in claim 47 wherein the key data includes 
a key and optionally at least one of: 

1) a second URL identifying the RPS; 

2) start date/time data identifying a date and time at which a key is valid; 

3) end date/time data identifying a date and time at which a key becomes invalid; 

4) lifespan data indicating a period of time over which the key is valid; 

5) key index data identifying the key from among a plurality of different keys; 

6) hash identifier data indicating to the RDS a hash algorithm to be performed to 
generate the hash data; 

7) encryption data indicating an encryption model and/or algorithm used to 
encrypt and decrypt resource access right data; and/or 

8) format fields data indicating the number of fields in the signal requesting 
access to the resource. 
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Claim 51 (withdrawn): A server storing a secure universal resource locator (URL) 
generator module executable by the server to generate a URL having secure resource 
access right data defining restriction(s) on a web access device (WAD) and/or user 
thereof to access a resource indicated by the secure URL such that the WAD can generate 
a request for the resource using the secure URL, the resource access right data secured by 
the server so that modification of the resource access right data can be detected. 

Claim 52 (withdrawn): The server as claimed in claim 51 wherein the server stores a 
secure content key database having key data, and the server executes the secure URL 
generator module to secure the resource access right data with the key data. 

Claim 53 (withdrawn): The server as claimed in claim 51 wherein the server appends the 
key data to an Internet protocol (IP) address of the WAD requesting the web page 
document from the server, and hashes the key data and the IP address to generate hash 
data, the hash data combined with the URL and resource access right data to generate the 
secure URL. 

Claim 54 (withdrawn): The server as claimed in claim 5 1 wherein the server uses the key 
data to encrypt the resource access right data and combines the encrypted resource access 
right data with the URL to produce the secure URL. 

Claim 55 (withdrawn): The server as claimed in claim 51 wherein the server comprises a 
resource access right database storing the resource access right data. 

Claim 56 (withdrawn): The server as claimed in claim 51 wherein the server comprises 
an access right enforcer module, the server executing the access right enforcer module to 
determine whether a resource is to be provided to another server in response to a request 
signal received from the other server via the Internet, the server executing a secure 
caching module to transmit the resource to the other server for distribution if the resource 
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access right data indicates that the other server is authorized to access the resource, and 
the server preventing access to the other server if the resource access right data indicates 
the other server is not authorized to access the resource. 

Claim 57 (withdrawn): A server of a resource distribution subsystem (RDS) storing an 
access right enforcer module executable by the server, the server executing the access 
right enforcer module in response to a signal from a web access device (WAD) 
requesting access to a resource, the request signal having a universal resource locator 
(URL) with secure resource access right data that was generated from a web page 
containing a secure URL provided by a resource provider subsystem (RPS), the server 
executing the access right enforcer module using resource access right data to determine 
whether the resource access right data has been modified after its establishment by the 
RPS, the server preventing access to the resource if the resource access right data has 
been modified after its establishment, the server further executing a secure caching 
module if the resource access right data has not been modified to provide access to the 
resource if the WAD is determined by the server to have the right to access the resource 
based on the resource access right data, and the server blocking access to the resource if 
the WAD is determined not to have the right to access the resource. 

Claim 58 (withdrawn): The server as claimed in claim 57 wherein the request signal 
received by the server from the WAD includes an Internet protocol (IP) address, a 
universal resource locator (URL) indicating the location of the resource, and hash data, 
the server retrieving key data based on the IP address and/or URL, the server combining 
the key data with at least the IP address and/or URL, the server generating hash data 
based on the key data and IP address and/or URL, the server comparing the server- 
generated hash data with the hash data in the request signal, the server executing its 
secure caching module to provide access to the resource if the hash data matches, and the 
server blocking access to the resource if the hash data do not match. 
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Claim 59 (withdrawn): The server as claimed in claim 57 wherein the server retrieves 
date/time data from a secure content key database stored therein, the date/time data 
indicating a period of time over which the key data is valid, the server recording the date 
and time of receiving the request signal at the server and comparing the date and time of 
receipt of the request signal with the date/time data to determine whether the key data is 
valid, the server permitting further processing of the request signal if the comparison 
indicates the key data is valid, and the server terminating further processing of the request 
signal if the date/time data indicates the key data is not valid. 

Claim 60 (withdrawn): The server as claimed in claim 59 wherein the server further 
retrieves from the secure content key database life span data that the server uses in 
conjunction with the date/time data to determine the period of time over which the key is 
valid so that date and time of receiving the request signal at the server can be compared 
by the server with the date/time data and lifespan data to determine whether the key is 
valid. 
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